3 ms·
Sounds like it completely defeats the point of encryption.
by wfunction 11y ago
Sounds like it completely defeats the point of encryption.
- jhallenworld 11y agoYou could store the key (or password to the key) in the TPM in order to prevent BIOS, bootloader or option ROM tampering. An issue is that too many things could affect the TPM PCR values (for example, plug in a USB stick even though you don't boot from it- I think this is a mistake in the spec), so users get used to typing in the backup password and may not notice that a root-kit was installed.
- MichaelGG 11y agoIn my experience of using Bitlocker for years, it's very rare that I have to enter the backup password. Even when I changed the default PCRs used.